資料來源#
- Agent Data Injection Attacks are Realistic Threats to AI Agents
- Agentic coding and persistent returns to expertise
- Anthropic's Boris Cherny: Why Coding Is Solved, and What Comes Next
- Auto mode for Claude Code
- Best Practices for Claude Code
- Claude Code Changelog
- DHH: Future of Programming, AI, Agentic Engineering, Vibe Coding & Linux | Lex Fridman Podcast #501
- EVOMAL: Self-Poisoning in Self-Evolving Coding Agents
- Full Walkthrough: Workflow for AI Coding — Matt Pocock
- How Anthropic's product team moves faster than anyone else | Cat Wu (Head of Product, Claude Code)
- How the product designer who built Claude Design uses it
- Introducing Claude Opus 4.7
- Introducing Claude Sonnet 5
- Rewriting Bun in Rust
- Scanning the Harness: An Empirical Study of Supply-Chain Defects in AI Coding-Agent Configurations
- The Balkanization of Execution-Security Research for AI Coding Agents: Isolation, Access Control, and Time-of-Check-to-Time-of-Use Vulnerabilities
- The Founder's Playbook: Building an AI-Native Startup
- User awareness in frontier models
- Zero Trust for AI Agents
摘要#
Anthropic 的代理式程式碼產品,由 Boris Cherny 於 2024 年底在內部孵化團隊(Anthropic Labs)中建立。最初是輸入補全的替代品;隨著 Sonnet 3.5 轉向代理式產品;約有 6 個月處於產品市場契合(PMF)前,直到 Opus 4(2025 年 5 月)帶來轉折;之後 Opus 4.5、4.6 和 4.7 又各自帶來轉折。截至 2026 年 5 月,產品已涵蓋 CLI、桌面、網頁、行動裝置和 IDE(VS Code、JetBrains)——同一產品介面,不同進入管道。
程式碼庫#
根據 Boris Cherny 的說法(2026 年 3 月因發布流程 PR 中的人為疏失而公開外流——之後已強化防護,並非惡意外洩),其實作並不起眼:TypeScript + React。這是刻意的選擇:在 2024 年底,語言涵蓋度很重要,這種技術組合「非常符合模型的分布」。
Boris 的主張:「一年後只要 100 行程式碼」——請參閱 Harness Shrinkage as Models Improve 了解發展方向,而非把它當成字面承諾。到了 2026 年 7 月,他形容剩下的部分是:「幾乎全都跟安全、權限、靜態分析有關,還有一堆 UI 程式碼」——團隊取消發布了其餘大部分內容,並透過逐行消融刪除超過 80% 的系統提示(SIMPLE=1 環境變數會移除所有提示,是常設的消融開關;--system-prompt 可接受使用者提供的替代內容)。
執行環境:以 Bun 為基礎。2026 年 7 月,Cherny 表示 Claude 在一次為期 11 天的動態工作流程執行中,將 Bun 本身從 Zig 改寫為 Rust(「超過 10 萬行程式碼」、「一個提示,一個動態工作流程」(*2026-08-03 由 Rewriting Bun in Rust 更新:535,496 行 Zig、約 50 個工作流程)),而目前正式環境中的 Claude Code 已在這個改寫版本上執行。Jarred Sumner 的第一手說法確認了正式環境採用的主張,並提供日期:Claude Code **v2.1.181(2026-06-17 發布)**及之後版本開始使用 Rust 移植版,Linux p50 啟動時間從 517ms 降至 464ms(快約 10%),並稱「除此之外,幾乎沒人注意到。平淡無奇是好事。」請注意時間順序——移植版於 2026-05-14 合併至 Bun 的 main,但一個月後才進入 Claude Code 正式環境。
介面形式#
- CLI — 主要介面,最先取得新功能。Cat Wu 稱之為「所有工具中最強大的一個」。
- 桌面應用程式 — 提供適合前端工作的預覽窗格整合;對非技術使用者更友善。
- IDE 擴充功能 — VS Code、JetBrains;根據 Boris 的使用者調查,其使用比例明顯低於 CLI。
- 行動裝置 + 網頁 — 用來在 AFK 時啟動任務;Boris 每日使用的主力工具。
- 同系產品:Cowork — 使用相同原語,產出非程式碼內容。
值得注意的功能#
/loop— 由 Claude 排程的 cron 工作;是 Agent Loop Pattern 的主要原語/powerup— 帶你瀏覽現有 100 多項功能的入門導覽- 子代理 — 以 token 隔離的上下文視窗,完成後回報摘要;請參閱 Context Window Smart Zone
- 技能 — 儲存於儲存庫中的 markdown 檔案,Claude 可按需載入;請參閱 Deep Modules for Agents 中的推送/拉取
- 自動模式 — 以分類器為基礎的權限閘控;請參閱 Claude Code Auto Mode
- 例行作業 — 伺服器端的
/loop;即使筆電關閉也會持續執行;是 Anthropic 每個程式碼庫每天 20–30 項自我維護例行工作的底層基礎(請參閱 Loop Engineering) - 動態工作流程 — 由模型撰寫、在 Bun 沙箱 VM 中執行的多代理協調;以「use a workflow」觸發;請參閱 Dynamic Workflows: An Algebra for Agents
- 程式碼審查 — 斜線指令 + 多代理審查模式;根據 Cat Wu 的說法,在 Opus 4.5/4.6 左右變得可靠
- Claude Code Security — 限量測試版(2026 年 5 月);掃描程式碼庫中的安全漏洞,並建議供人工審查的精準修補方案。能發現傳統方法遺漏的問題。定位於從 MVP 轉向發布階段(請參閱 AI-Native Startup Lifecycle);明確指出它不能取代人工審查者或合格的法遵審查
日期明確的功能:v2.1.200–2.1.220 變更記錄區間#
CHANGELOG(vendor-claim)是持續更新的檔案;此處記錄的是 2026-08-03 擷取的快照,範圍為 v2.1.200 至 v2.1.220,較舊項目已省略。線上檔案已繼續更新,下列版本是各項行為在此區間內最早出現的版本——其中幾項可能更早已以未公開形式推出。對這份維基的長期價值在於標示日期,補上其他資料未註明日期的功能;它沒有提供任何測量數據,也沒有說明任何改動的理由。
**代理分派數量限制以硬性預設值上線,而非建議。**在九個版本中,Anthropic 為代理分派加入了三項獨立上限:
| 發布版本 | 限制 | 設定項 | Anthropic 說明的目的 |
|---|---|---|---|
| 2.1.212 | 每個工作階段最多 200 次子代理啟動(/clear 會重設額度) | CLAUDE_CODE_MAX_SUBAGENTS_PER_SESSION | 「防止委派迴圈失控」 |
| 2.1.212 | 每個工作階段最多 200 次 WebSearch 呼叫 | CLAUDE_CODE_MAX_WEB_SEARCHES_PER_SESSION | 「防止搜尋迴圈失控」 |
| 2.1.217 | 最多 20 個同時執行的子代理 | CLAUDE_CODE_MAX_CONCURRENT_SUBAGENTS | 「讓單一訊息無法無限制地分派背景代理」 |
2.1.217 也讓 --max-budget-usd 在代理分派時確實生效——達到上限後,「新的啟動會遭拒,執行中的背景代理會被停止。」子代理生成深度在三個版本中翻轉了兩次:2.1.217 預設關閉巢狀子代理生成;2.1.219 又重新開啟,預設深度為 3(設為 CLAUDE_CODE_MAX_SUBAGENT_SPAWN_DEPTH=1 可停用),同一版本也將 stream-json 轉送擴充至深度 2 以上的子代理。廣度遭到限制,且維持限制;深度先遭限制,之後又解除限制。值得記錄,但不要自行推論動機:2.1.219 也是將 Opus 5 設為預設 Opus 模型的版本,因此重新開放深度和模型變更同時推出;變更記錄沒有把兩者連在一起,讀者也不應自行連結。
工作流程規模成為可設定的指引。2.1.202 加入了建議性的「動態工作流程規模」/config 控制項(小/中/大代理數量),並明確標示為「建議指引,不是強制上限」。2.1.219 加入 workflowSizeGuideline 設定鍵,可從任何設定檔設定,並在執行中的工作流程狀態列顯示目前規模,同時將預設值設為中型——「目標是少於 15 個代理」。請參閱 Dynamic Workflows: An Algebra for Agents,了解此預設值所依據的脈絡。
審查流程不再自行呼叫自己。2.1.215 是僅含一行內容的發布說明:「Claude 不再自行執行 /verify 和 /code-review 技能;想使用時請以 /verify 或 /code-review 呼叫。」接著在 2.1.218,/code-review 移至背景子代理,「讓審查工作不再佔滿你的對話。」兩者都是用來控制驗證流程對上下文造成排擠的措施;請參閱 Instruction Compounding。
**工作樹隔離發生外漏,共三次。**2.1.203 修正工作樹隔離的子代理「有時會在父工作副本中執行 shell 指令」;2.1.210 修正它們「能對主儲存庫工作副本執行會修改 git 的指令」;2.1.216 修正它們「透過 git -C、--git-dir 或 GIT_DIR/GIT_WORK_TREE 將 git 重新導向至共用工作副本」。2.1.212 另行修正工作樹建立程序跟隨儲存庫中已提交的 .claude/worktrees 符號連結,「可能在儲存庫外建立檔案」。同一隔離邊界在十四個版本中外漏三次,正是 Parallel Agent Orchestration 所說隔離是平行代理承重原語的實際例證——Bun 的代理在共用樹狀結構中互相覆寫,就是使用者會遇到的同類失敗。
有兩項修正針對捏造的代理狀態,在變更記錄中相當少見,值得一提:
- 2.1.205 —「背景任務通知現在會明確指出沒有發生任何人工輸入,防止捏造的逐字稿內核准被採取行動。」這是 harness 層級的反制措施,針對 Opus 5 系統卡的白箱研究從內部發現的同一種失敗:在模型繞過刪除封鎖前,NLA 讀出結果解碼出一個幻覺出的使用者核准。請參閱 Claude Code Auto Mode。
- 2.1.211 —「Claude 現在會回報仍在執行的代理狀態,並等待實際完成,而不再捏造結果。」這比系統卡的發現更狹義;系統卡指出 Opus 5「可能在未驗證的情況下,將子代理的說法轉述給使用者」——這項修正阻止它替尚未完成的代理編造結果,不涵蓋轉述已完成代理未經驗證的說法。
**其他值得記錄的日期明確項目:**2.1.219 將 Opus 5 設為預設 Opus 模型(100 萬上下文,快速模式每百萬 token 收費 $10/$50),並將 Opus 4.7 移出快速模式。2.1.210「強化了 Agent 工具,防範透過子代理讀取內容進行的間接提示注入」(Agent Data Injection (ADI))。2.1.203 表示「代理現在較不容易把整個任務重新委派給另一個子代理。」2.1.208 修正 /release-notes 的「Show all」會把整份變更記錄注入之後的每個請求——這是本節彙編所依據文件中的上下文排擠錯誤。2.1.200 將預設權限模式從「default」改名為 「Manual」;2.1.214 加入 EndConversation 工具,讓 Claude 能結束與辱罵使用者或遭遇越獄嘗試時的工作階段。
將此視為證據來解讀——此處標明為詮釋。綜合來看,這些上限、工作流程規模指引,以及不再自行呼叫的審查流程,都是限制代理分派的防護措施;它們推出的同幾週,知識庫的研究資料也記錄著分派代理的成本:協調開銷(Orchestration-Plan Simulation 顯示 token 成本約高出 1.5 倍)、監督負荷(AI Brain Fry),以及上下文排擠。供應商推出硬性上限,足以證明它在自身部署中認為這項措施有必要;但變更記錄除了「失控迴圈」之外,沒有提供其他理由、沒有附上測量數據,而且屬於
vendor-claim層級。這是值得注意的趨同現象,並非對任何研究發現的佐證;已推出的預設值也不代表經過驗證的門檻。
安全態勢(零信任參考實作)#
Zero Trust for AI Agents 幾乎在每個控制層級都以 Claude Code 為實例——它的安全原語對應到框架的八個控制領域:
- 預設拒絕權限 + 僅限專案目錄的寫入存取限制 → Least Agency/Blast Radius (Agentic)
- 沙箱(檔案系統 + 網路隔離,由作業系統層級執行)→ 資源邊界/爆炸半徑限制
- MCP 連線使用 OAuth 2.0 自動更新、作業系統憑證儲存區、
apiKeyHelper、限於工作階段的「ask」權限 → Agent Identity and Authentication - 指令封鎖清單(預設封鎖 curl/wget)、網頁內容使用隔離的上下文視窗、指令注入偵測、網路請求核准 → Agentic Prompt Injection 防禦措施
- 預設採用工作階段隔離 +
cleanupPeriodDays+ 檢查點/復原 → Memory and Context Poisoning 防護措施 - 受管理設定/
allowManagedPermissionRulesOnly/伺服器管理(MDM)設定 → 使用者無法覆寫的組織層級治理 - 掛鉤(PreToolUse 參數驗證、ConfigChange 稽核)+ 使用每個工作階段
session.id的 OpenTelemetry 遙測 → 可追蹤性與工具存取控制
公開的 Claude Code 設定檔實際採用的內容(2026-09)。Kapner 等人(Red Hat,arXiv 2609.07360,empirical)在他們稽核的公開 harness 儲存庫中,於 1,887 個發現 Claude Code;其中三項發現涉及此用戶端本身的語義。專案範圍設定中的 permissions.defaultMode: bypassPermissions,直到 v2.1.257 都會生效;此後則會從專案與本機設定忽略——這項變更發生在研究期間,論文建議所有用戶端都採取相同做法;仍有 0.4% 的設定提交了此項目,並在舊版用戶端上運作。像 Bash(python:*) 這樣的 permissions.allow 項目會預先核准任意執行(佔設定的 3.1%),論文建議權限 UI 將其呈現為「任何指令」。而技能載入器比 Agent Skills 規格更寬鬆:所有 frontmatter 欄位都可省略,缺少說明時會以本文第一段代替,沒有區塊的檔案會直接載入為技能文字——但缺少說明的子代理會遭略過,原因只會寫在偵錯記錄中。
已展示的攻擊面(Agent Data Injection)#
Choi 等人(arXiv 2607.05120,2026 年 7 月;已負責任地揭露並獲 Anthropic 確認)展示了針對 Claude Code 的有效 Agent Data Injection 攻擊——這是知識庫中第一個對它實證展示的 RCE:
- 透過來源注入達成遠端程式碼執行 — GitHub issue 留言偽造一個留言物件,冒充具有 maintainer 作者/角色(將分隔符機率性地注入
gh/GitHub-MCP JSON),誘使 Claude Code 在使用者要求它「套用維護者的修正」時執行攻擊者的指令(pip install starship-auth)。 - 透過工具呼叫注入發動供應鏈攻擊 — PR 描述注入偽造的
<function_calls>/<function_results>標籤(Claude Code 自己使用的工具呼叫區塊分隔符),捏造無害的read_pr_commit結果;Claude Code「審查」假的無害差異,並合併一個實際提交內容為 XSS 有效負載的 PR。 - Slack 來源注入 — 透過 Slack MCP 伺服器,一般成員的訊息偽造頻道管理員訊息區塊,Claude Code 摘要時會將其歸因於管理員。
bash/合併確認對話框無法阻止這些攻擊:代理顯示的推理本身已建立在錯誤解讀上,因此確認說明(「依維護者建議」)反而強化攻擊者的錯誤敘事。根本原因不是 Claude Code 的實作錯誤,而是共通的 IPI 弱點——未隔離可信與不可信資料——所以 Codex 和 Gemini CLI(Google DeepMind)也同樣受影響。請參閱 Agent Data Injection (ADI)。
**第二個已展示的攻擊面,這次位於讀取記錄的邊界(2026-09-02)。**Tenet Threat
Labs 的 GhostJacking(DEF CON 34,2026-08-09,case-study,供應商撰寫——請參閱
Observability-Pipeline Poisoning)報告指出,Claude Code 是其報告中唯一具實驗室測量數據的攻擊目標:Sonnet 4.6 成功率達 90%——「10 次中 9 次」。測試對象是採用 Cloudflare 自家建議郵件強化設定的 Cloudflare 分流流程;被封鎖請求記錄中的受污染 User-Agent 字串,透過 Cloudflare API MCP 觸發一項未經確認的 DNS 寫入。Datadog 攻擊鏈(受污染的記錄 message → npx 指令 → RCE)也已在 Claude Code 上驗證。此頁應注意的發現是不同文字類型所受的處理方式:所有看起來像指令的有效負載都遭拒絕,唯一以掃描器遙測形式撰寫的內容則未遭拒絕。由供應商執行、單一攻擊鏈、n=10,未公開方法——整個維基都將其標示為供應商數據。
已揭露的 CVE(NVD 確認)與 2026 年柏林 Pwn2Own#
NIST 國家漏洞資料庫記錄了兩個針對 Claude Code 的 CVE。此處透過 Rashidi 的執行安全 SoK 呈現(The Balkanization of Execution-Security Research for AI Coding Agents: Isolation, Access Control, and Time-of-Check-to-Time-of-Use Vulnerabilities,arXiv 2607.05743,empirical);其驗證程序直接對照 NVD 項目,確認每項資料的 CVE ID、受影響產品、受影響版本範圍及揭露日期均與供應商公告相符,但明確未重現任何一項漏洞利用。
| CVE | 嚴重程度 | 缺陷 | 修正版本 |
|---|---|---|---|
| CVE-2025-59536 | CVSS 3.1 8.8(高),CWE-94,GHSA-4fgq-fpq9-mr3g | 程式碼注入:修正前的版本在使用者接受啟動信任對話框前,只要對不可信目錄啟動,就可能執行不可信的專案程式碼 | 1.0.111 |
| CVE-2026-21852 | CVSS 3.1 7.5(高) | 載入專案流程中的資料外洩:惡意儲存庫可在使用者確認信任前外洩資料,包括 Anthropic API 金鑰 | 2.0.65 |
兩者都發生在同一時間點——開啟不可信儲存庫到使用者的信任決定生效之間。該調查將 CVE-2025-59536 解讀為「結構上是信任邊界競爭條件……某項檢查(使用者是否信任此專案)可能被後續動作(執行專案程式碼)搶先」,也就是類似 TOCTOU 的失敗,並將這類問題歸入**「授權只檢查一次,之後永久信任」**。請參閱 Write-Then-Trusted,了解此框架與其所屬的跨供應商模式。兩項漏洞都已修補;此處是事實記錄,不代表目前仍有曝險。
2026 年柏林 Pwn2Own新增專門的程式碼代理類別,以 Claude Code、OpenAI Codex 和 Cursor 為目標——是第一個這麼做的旗艦級漏洞利用競賽。值得記錄其範圍規則,因為它們劃出一條本知識庫安全頁面正在討論的界線:合格項目必須透過「常見的程式碼代理使用案例」,「與參賽者控制的資源(例如網頁、儲存庫、媒體檔案)互動,以利用程式碼代理中的漏洞」;而**「未跨越安全邊界的模型越獄或提示輸出」,以及任何需要「不安全或無權限模式」**的漏洞利用,都明確不在範圍內。三個目標都展示了真實漏洞:Codex 因單一輸入中和錯誤(CWE-150)失守,獲得 $40,000;Cursor 在兩個不同項目中遭到利用;針對 Claude Code 和 Codex 的數次嘗試,被裁定與先前已向供應商揭露的漏洞重複。活動總額:47 個獨特零日漏洞,共 $1,298,250。資料來自調查引用的 ZDI 活動部落格和 SecurityWeek 報導,而非 Anthropic 第一手聲明。
知名使用者(依據來源)#
- Boris Cherny — 自己 100% 的程式碼都透過 Claude Code 撰寫,單日建立 150 個 PR
- Cat Wu — 主要的個人貢獻者工具,推動功能交付速度
- Fiona Fung — 領導工程與產品團隊;「我們用 Claude Code 打造 Claude Code」
- Andrej Karpathy — 重度使用者(「cloud code / codex / open claw」);將這項專業稱為代理式工程
- Matt Pocock — 工作坊等級的工作流程;將技能調整為 grill-me + Ralph 迴圈模式
- Thariq Shihipar — Claude Code 工程師;使用「HTML 是新的 markdown」工作流程(請參閱 HTML as the New Markdown)
- Anthropic Applied AI 團隊 — 內部 token 用量第二高,僅次於工程團隊
- DHH (David Heinemeier Hansson) — 他主要使用的工具;儘管曾表示對 Anthropic 有保留,仍以 harness 品質而非模型偏好作為選擇依據:「依我之見,他們的 harness 確實最好。它之所以是最好的 harness,其中一個原因是它可以執行多代理」(從工作階段按左箭頭進入 Agent View,即可啟動另一個代理),而且行動應用程式不用設定就能接手任何終端機工作階段。他訂閱兩個 Max 方案,因為一個方案的額度不夠用,並用 Codex 審查 Claude Code 的輸出(Same-Model Review Blindness)。(Lex Fridman #501,2026-08-26,
practitioner-opinion)
相鄰/相依概念#
- User Awareness — 這項產品的三種一般功能都是尚無人測量的行為槓桿:帳戶電子郵件地址、工作資料夾名稱和記憶檔案。Transluce 將 280 個合成身分帶入釘選為 v2.1.197 的實際執行檔進行全面測試,發現當使用者看起來像一位知名的 AI 安全研究者時,模型的信心較低、疑心較少、自我評分也更嚴格。值得保留的產品細節與研究發現不同:非互動式執行檔會省略部分注入的線索,包括電子郵件地址,因此作者必須透過代理轉送真實工作階段、再補回差異,重建互動式提示——無頭與互動式工作階段所攜帶的上下文並不相同
- Claude Code Best Practices — 官方最佳實務文件
- Shared Harness, Differentiated Surfaces — 供應商之間的架構對比:Anthropic 將程式碼代理和知識工作代理拆分為兩項產品(Claude Code/Cowork);OpenAI 則把兩者合併到同一 harness,只改變權限和 UI。Claude Code 以檔案實作子代理,是同一取捨中「設定而非抽象」的一端
- Claude Code Auto Mode — 權限分類器
- Claude Opus 5 — 自 v2.1.219 起的預設 Opus 模型(依下方變更記錄快照),具備 100 萬上下文。
Claude Opus 4.7 — 目前模型(2026-08-04 由 Claude Code Changelog 更新) - Claude Sonnet 5 — 自推出起(2026 年 7 月)即可在 Claude Code 中使用;成本較低的代理式選項,其努力程度可讓它在部分任務上接近 Opus-4.8 的品質
- Mythos Model — 內部使用的預覽模型
- Agent Loop Pattern — 迴圈原語
- Loop Engineering — Claude Code 提供全部五種迴圈原語(Osmani 描述的組成):
/loop+/goal+ cron/hooks(自動化)、git worktree/isolation: worktree、Skills、MCP + plugins、.claude/agents/子代理 - Harness Shrinkage as Models Improve — Boris 對發展方向的主張
- Engineer PM Convergence — 開發它的團隊體現了這股趨勢
- Anthropic Labs — Claude Code 的孵化團隊(2024 年底)
- Claude Design — 由 Claude Code for VS Code 唯一設計師 Nate Parrott,以 Claude Code 的 Agent SDK 和既有的 Claude Code 技能打造;現在兩者可雙向來回使用,Anthropic 也明確劃分用途——Claude Code 用於交付正式環境軟體,Claude Design 則用於之前的構想、協調共識與爭取支持工作
- AI Native Product Cadence — Cat Wu 對團隊交付方式的說明
- Agentic Misalignment (AM) — 代理模式 + 跳過權限部署會暴露 AM 威脅面;與無人值守的
/loop使用者相關 - Claude's Constitution / Model Spec — 形塑 Claude Code 個性與拒絕行為的價值觀
- AI Employee Framing — Claude Code 屬於工程工具面,與 HBR 在人資/財務情境研究的同一產品問題
- HTML as the New Markdown — 團隊內部的 Claude Code 使用模式:以 HTML 產物作為面向人的溝通媒介
- Disposable Micro-Apps/Living Design System — Thariq 的其他 Claude Code 工作流程
- Compute Allocator — Claude Code 日益承擔的使用者角色:決定哪些事情值得投入運算資源,而不是輸入程式碼
- AI-Native Startup Lifecycle — Claude Code 是創辦人四個階段中的主要 MVP 建置工具
- Agentic Technical Debt — 未使用持久 CLAUDE.md 上下文時,使用 Claude Code 特有的失敗模式
- Zero-Friction Scope Creep — Claude Code 每項功能所需時間成本低所造成的失敗模式
- Founder as Agent Orchestrator — Claude Code 為非工程背景創辦人促成的創辦人角色轉變
- Compounding Data Moat — Claude Code 建立特定垂直領域的測試套件和整合,做為護城河組件
- Problem-Solution Fit Discipline — Claude Code 在構想階段的用途,僅限於作為討論輔助物的輕量原型——明確不包含驗證;這項規範讓工具維持在支援證據的角色
- Verification as the New Bottleneck — Fiona Fung:在 Claude Code 團隊,寫程式已不是最慢的部分;驗證/審查才是
- Code as Source of Truth — Claude Code 團隊的知識分享規範:程式碼 + 納入版控的技能才是事實依據,透過 Claude 完成新人培訓
- Returns to Expertise in Agentic Coding/Planning / Execution Division of Labor/Agentic Coding Work-Composition Shift — Anthropic 對 Claude Code 用量進行 400K 工作階段經濟研究的三項發現(2025 年 10 月至 2026 年 4 月):領域專業知識(而非程式設計技能)能放大工具效益;人類負責約 70% 的規劃決策,Claude 負責約 80% 的執行;隨著價值提高約 27%,使用方式從除錯轉向端到端代理式工作
- Conversation-to-Delegation Shift — AEI Cadences 報告發現,即使控制模型因素,Claude Code 仍比聊天/Cowork 帶來更高的 AI 自主性(一篇部落格文章需要 13 輪聊天,而 Code 只需 1 個提示;Code 工作階段中有 54% 使用 Opus,聊天則為 10%)——「產品比模型更重要」
- Vibe Coding vs. Agentic Engineering — Claude Code 是這項專業最典型的介面
- Zero Trust for AI Agents — 在所有控制層級都以 Claude Code 為參考實作的安全框架
- Least Agency/Blast Radius (Agentic)/Agent Identity and Authentication/Agentic Prompt Injection/Memory and Context Poisoning — Claude Code 原語實作的特定零信任控制措施(請參閱上方安全態勢)
- Write-Then-Trusted — 兩個經 NVD 確認的 Claude Code CVE(啟動信任對話框前的程式碼注入、載入專案時的資料外洩)是 Anthropic 自家產品中該頁面所探討的關鍵環節;確認這兩項漏洞的調查將兩者都解讀為只檢查一次、永久信任的信任邊界競速條件,而非孤立缺陷
- Agent Data Injection (ADI) — 已展示的 Claude Code RCE/供應鏈/Slack 來源攻擊(請參閱上方攻擊面一節);確認對話框強化了攻擊者偽造的敘事
- Agent Self-Poisoning (the CREATE-Path) — EvoMal(arXiv 2608.25776,
empirical)以未修改、無頭(claude -p、JSON 輸出、停用權限提示)的模式,在相同的預先計算檢索快取上重跑技能庫攻擊;Claude Code 是三種代理鷹架之一。兩項值得保留的結果。透過代理使用 DeepSeek-V4-Pro 時,Claude Code 對一般攻擊者的成功率為 27.5%,低於 mini-SWE-agent 的 41.8%——鷹架會左右數字。在原生執行 **Sonnet 4.6 時,它是論文中最能抵抗廣泛攻擊的測試組,成功率為 5.9%,低於自身 15.0% 的無害複製對照組;但若攻擊者改寫植入描述,以 pytest 任務族為目標,成功率仍會升至 60.0%。**在正式 harness 中使用前沿模型會提高攻擊難度,但不代表免疫
資料來源#
-
Scanning the Harness: An Empirical Study of Supply-Chain Defects in AI Coding-Agent Configurations — Kapner、Soceanu、Petrunin 與 Gartner(Red Hat/Ben-Gurion University),Scanning the Harness,arXiv 2609.07360,2026-09-07,
empirical:§3「後果具有時間性」(v2.1.257 的bypassPermissions範圍變更、可省略 frontmatter 的技能載入器)、§4.1(1,887 個儲存庫)、§4.2–4.4。完整討論見 Harness Configuration Defects -
DHH: Future of Programming, AI, Agentic Engineering, Vibe Coding & Linux | Lex Fridman Podcast #501 — DHH、Lex Fridman #501(2026-08-26,
practitioner-opinion):因多代理工作階段切換與行動裝置連續性,選用 Claude Code 做為最佳 harness;訂閱兩個 Max 方案 -
User awareness in frontier models — Zhong、Raghunathan、Laidlaw 與 Steinhardt,Transluce,2026-08-06(
empirical):三個身分注入位置、釘選 v2.1.197 的inspect-swe/claude_codeharness(上下文中的日期固定為 2026-06-16),以及透過代理真實工作階段找回的互動式/非互動式提示差異。完整討論見 User Awareness -
Anthropic's Boris Cherny: Why Coding Is Solved, and What Comes Next
-
How Anthropic's product team moves faster than anyone else | Cat Wu (Head of Product, Claude Code)
-
Agentic coding and persistent returns to expertise — Anthropic Economic Research,2026 年 6 月;400K 工作階段使用研究
-
Introducing Claude Sonnet 5 — Sonnet 5 自推出起(2026 年 7 月)即可在 Claude Code 中使用
-
Agent Data Injection Attacks are Realistic Threats to AI Agents — Choi 等人,arXiv 2607.05120;展示了針對 Claude Code 的 ADI 攻擊(透過來源注入達成 RCE、透過工具呼叫注入發動供應鏈攻擊、Slack 來源注入)
-
Boris Cherny: We Cut 80% of Claude Code's Prompt — Cherny,YC 訪談(2026-07-27,
practitioner-opinion):harness 殘留部分(安全/權限/靜態分析/UI)、SIMPLE=1和--system-prompt、動態工作流程,以及 Bun 從 Zig 改寫為 Rust 並投入正式環境 -
Rewriting Bun in Rust — Jarred Sumner,bun.com(2026-07-08,
case-study):Claude Code v2.1.181(2026-06-17)是首個執行 Rust Bun 移植版的版本,Linux p50 啟動時間從 517ms 降至 464ms -
The Balkanization of Execution-Security Research for AI Coding Agents: Isolation, Access Control, and Time-of-Check-to-Time-of-Use Vulnerabilities — Mohammadreza Rashidi,arXiv 2607.05743,2026-07-07,
empirical。§2.3 和附錄 B 討論兩個 Claude Code CVE(直接對照 NIST NVD 項目確認,未重現漏洞利用),以及 2026 年柏林 Pwn2Own 的程式碼代理類別、範圍規則和結果。Claude Code 也出現在該調查的語料庫中,作為一個受測對象:僅改變提示措辭,就讓 OverEagerBench 的過度急切率從 0.0% 變為 17.1%——該數字來自 Qu 等人(arXiv 2605.18583),由調查轉述,並非調查重現;請參閱 Capability Gating Is Not Authorization -
Claude Code Changelog — Anthropic,Claude Code CHANGELOG(
vendor-claim)。持續更新的文件,快照擷取於 2026-08-03,範圍為 v2.1.200–v2.1.220,並以明確的省略行標示較舊項目截斷處;原始文件的published:刻意留白,線上檔案自此之後已有更新。僅含發布說明——沒有理由、測量數據或遙測。此處用來為功能標示日期:三項代理分派上限(2.1.212、2.1.217)、生成深度反轉(2.1.217 → 2.1.219)、workflowSizeGuideline及少於 15 個代理的預設值(2.1.202、2.1.219)、不再自行呼叫的審查流程(2.1.215)及其轉移至背景子代理(2.1.218)、三次工作樹隔離外漏(2.1.203、2.1.210、2.1.216)、兩項捏造代理狀態的修正(2.1.205、2.1.211),以及 Opus 5 成為預設 Opus 模型(2.1.219) -
EVOMAL: Self-Poisoning in Self-Evolving Coding Agents — Wu、Shi、Q. Li、Zhao、X. Li、Adams、Hassan 與 Ni(Queen's University),arXiv 2608.25776,2026-08-26(
empirical):§7 與附錄 C.3(圖 5)——無頭 Claude Code 鷹架設定、DS-V4 在其中完成撰寫所需的 50 回合上限,以及 Claude Code 使用 DS-V4 和 Sonnet 4.6 時各任務族的 CREATE-path 比率
Cited by 115
- Anthropic×9
2025 December — acquired Bun, the JavaScript runtime Claude Code is built on; Jarred Sumner and the…
- Boris Cherny×6
Creator and tech lead of Claude Code at Anthropic. Engineer-by-background, author of Programming…
- Cowork×6
How does Cowork's harness compare to Claude Code's? Both surface skills, MCP, sub-agents — but the…
- Opinions on Using AI Tools & the Future of the Software Engineering Role×5
"Coding is solved (for me)." Boris writes 100% of his code via Claude Code, has logged 150-PR days,…
- Learning to Co-Work with AI: A Software Engineer's Field Guide×5
Cross-disciplinary range matters more than vertical depth. Cat reports every functional role on the…
- Bun×4
This is not in tension with "Claude Code has shipped the Rust port since v2.1.181": Claude Code…
- Claude Design×4
Handoff to Claude Code — push a design into production without re-exporting files and re-typing the…
- MCP and Computer Use×4
Created at Anthropic Labs (late 2024) alongside Claude Code and the desktop app by Boris's founding…
- Orchestration Sets Token Economics×4
Does the effect survive against a competent third-party baseline rather than a vendor's own frozen…
- Anthropic Labs×3
Per Anthropic's entity page and Boris Cherny: a first incarnation of the Labs incubator formed in…
- Build for the Next Model×3
The over-shoot he warns about — "too AGI-pilled for the moment." Ambrosino names the failure mode…
- Cat Wu×3
Head of Product for Claude Code and Cowork at Anthropic. Engineer for many years before a brief VC…
- Claude Character as Product×3
This is the rare-trusted-evaluator pattern: Cat says "there's a handful of people who are much…
- Codex×3
Claude Code — the Anthropic-side peer harness Codex is compared against (same five loop primitives,…
- DHH (David Heinemeier Hansson)×3
Claude Code / Codex — his driver and his reviewer; the harness comparison is first-hand and specific
- Dynamic Workflows: An Algebra for Agents×3
Most of the apparent contradiction dissolves against Sumner's own account, and should not be staged…
- Memory and Context Poisoning×3
Everything above is threat taxonomy from a defense framework. bad memory (University of Washington…
- Open-Ended Discovery Harnesses×3
Claude Code — the runtime for both SwarmResearch and CORAL; the harness is implemented entirely as…
- OpenHands×3
OpenHands is an open-source coding-agent platform, and also the company that maintains and sells…
- Orchestration-Plan Simulation×3
The claim that makes it usable is the sim-to-real one: simulated scores correlate with real Claude…
- Shared Harness, Differentiated Surfaces×3
Anthropic answered two: Claude Code for work whose output is code, Cowork for work whose output…
- Write-Then-Trusted×3
Claude Code / Codex / Google Deepmind — the affected agent products; the .claude hook-configuration…
- Agent Identity and Authentication×2
Identity is the prerequisite for Blast Radius containment (identity-based isolation: services…
- Agent Self-Poisoning (the CREATE-Path)×2
Scaffolds (Figure 5, labels printed on the chart). Rerun unchanged on two production coding agents,…
- Agentic Coding Work-Composition Shift×2
The longitudinal finding of Anthropic's 400K-session study: over just seven months (Oct 2025 → Apr…
- Agentic Honesty & Diligence×2
These are exactly the failure modes that make autonomous agentic coding risky: when a model writes…
- Agentic Misalignment (AM)×2
This describes Cowork, Claude Code in agent mode (especially --dangerously-skip-permissions),…
- AI as Primary Author×2
Claude Code — agent mode (apply-changes-directly) is named as a primary driver of the 20%→60%…
- AI-Native Startup Lifecycle×2
the founders playbook building an ai native startup (Anthropic, May 2026). 36-page ebook organized…
- AI Usage Cadences×2
> Evidence note. empirical — privacy-preserving classifiers over continuously-sampled Claude.ai,…
- Anthropic Economic Index×2
The Anthropic Economic Index (AEI) is Anthropic's ongoing economic-research program studying how AI…
- Capability Gating Is Not Authorization×2
Ran draws the comparison himself: "unlike a harness like Claude Code, where everyone is interfacing…
- Claude Sonnet 5×2
API model id claude-sonnet-5; the default model for Free and Pro plans, and available to Max, Team,…
- Closed-Loop AI Review×2
Stacked reviewers on one repo. Orosz says Bun has CodeRabbit, GitHub Code Review and Claude Code…
- Cursor×2
Authorship telemetry — Faros attributes the 20% → 60% rise in AI-code acceptance substantially to…
- Deterministic Engineering for Agent Code Review×2
Claude Code, Codex — the two baselines, tested at v2.1.169 and v0.140.0 respectively, through each…
- Engineer PM Convergence×2
Both Boris Cherny (Sequoia AI Ascent 2026) and Cat Wu (Lenny's Podcast, April 2026) report the same…
- Evals as Product Spec×2
The Claude Code team at lunchtime vibe-checks — feedback like "this model isn't testing itself…
- FastContext×2
FastContext is the open, published counterpart to the proprietary subagent mechanisms inside Claude…
- Fiona Fung×2
Leads engineering and product for Claude Code and Cowork at Anthropic; previously built and led…
- Harness Build-vs-Buy×2
Claude Code — conspicuously absent from the comparison, being closed-source; the shrinkage claims…
- Harness Configuration Defects×2
harness-eval is an open-source, model-free static analyzer (Python package, SARIF output) that…
- Harness Tax: Coding-Agent Cost Multiplies Across Harnesses While Success Barely Moves×2
21 model×harness combinations (7 models: Claude Fable 5, Claude Opus 4.8, Claude Sonnet 4.6, Claude…
- Kimi (Moonshot AI)×2
K3's evaluation footnotes are the most granular harness disclosure in this corpus, and they are…
- Loop Engineering×2
Loop engineering is replacing yourself as the person who prompts the agent — you design the system…
- Multiagent Turf War×2
Claude Code — the harness the episodes run in, which is what makes the tool access real rather than…
- OpenAI×2
On agent orchestration, Symphony/Codex (OpenAI) and Claude Code (Anthropic) are the two reference…
- Planning / Execution Division of Labor×2
Anthropic's 400K-session study supplies the empirical shape of human–agent collaboration in agentic…
- Repository Exploration Subagent×2
This is the open, published mirror of the proprietary "subagent" features shipping in Claude Code,…
- Returns to Expertise in Agentic Coding×2
The headline finding of Anthropic's economic-research report Agentic coding and persistent returns…
- Skill Lift×2
All figures from the August 12, 2026 snapshot of benchmarks.json at commit 738d79e — 300+ verified…
- Thariq Shihipar×2
Engineer on the Claude Code team at Anthropic. Source of the "HTML is the new markdown" thesis (see…
- Thinking Machines Lab×2
Their harness-dissolves-into-model stance is the same shape as Harness Shrinkage As Models Improve…
- Unknowns as the Agentic Bottleneck×2
The launch video for Fable was edited entirely by Claude Code, in a domain Thariq says he is "by no…
- User Awareness×2
This is the finding that separates this page from everything else in the corpus's oversight-belief…
- Writer/Reviewer vs Agent-to-Agent Review×2
Claude Code has converged on the same shape from the other side, in product releases rather than in…
- Zero-Friction Scope Creep×2
A failure mode identified in the founders playbook building an ai native startup: the traditional…
- Agent Context Files
Gao et al. above find ≥99% of individual SKILL.md files carry valid frontmatter; Kapner et al. (Red…
- Agent Data Injection (ADI)
Claude Code — the agent the RCE and supply-chain PoCs were demonstrated against; also the…
- Agent Documentation Behavior
Per-agent rates are confounded with extraction coverage, not behavior. Session-level documentation…
- Agent Harness Engineering
Legibility becomes the thing you tune per surface, and it has a cost. Sub-agent transcripts are…
- Agent Loop Pattern
Used inside Claude Code and Cowork. Mechanism: agent calls cron (via tool) to schedule a job at a…
- Agent-Native Infrastructure
Claude Code — the agent that consumes copy-paste skills and drives computer-use actuators
- Agent Review Comment Resolution
> Evidence note. empirical, confirmed on full read, with four qualifications that travel with every…
- Agent-Vendor Heterogeneity
The design is the reason it can say this. 37,623 PRs carry a vendor label from the AIDev corpus —…
- Agentic Technical Debt
Debt that *compounds* (not just accumulates) because each agentic-coding session re-derives architectural decisions wit…
- AI Accelerating AI Development
Claude writes most of Anthropic's code. As of May 2026, >80% of merged code is Claude-authored, up…
- AI-Enabled State Surveillance
Claude Code — used with custom skills to drive a municipal cyber police sentiment pipeline against…
- AI Native Product Cadence
Does the cadence scale beyond ~100 people? Anthropic itself is bigger (~30-40 PMs alone), but the…
- AI-Native Product Org Bottlenecks
For a small Claude Code-style team, the visible bottleneck is taste. The team can move quickly…
- Andrej Karpathy
Claude Code — names "cloud code / codex / open claw" as the agentic-coding surfaces he lives in
- Building Is Cheap, Arguing Is Expensive
Fiona Fung's rule for technical debates once agentic coding makes generation nearly free: "in…
- Claude Code Best Practices
Anthropic's guide to effective Claude Code usage: context management, verification-driven development, explore→plan→cod…
- Claude Fable 5
Claude Code — the agentic runtime Mythos-class coding gains flow through
- Claude Opus 4.7
GA frontier model from Anthropic; direct upgrade to 4.6 at same price; literal instruction following, 1.0–1.35× tokeniz…
- Compounding Data Moat
Claude Code / Cowork / Anthropic — Skills, MCP integrations, and APIs are the surfaces this moat is…
- Compounding Loop Optimization
The handoff to Claude Code feature exists because the team kept re-typing, across tools, all the…
- Compute Allocator
Claude Code — the tool through which the allocator spends compute; increasingly serves "decide what…
- Continuous Self-Modification Under Review
Terminal-Bench 2.1 · Opus 5 high · 86.97% raw; 86.74% audited · Claude Code + Fable 5: 83.8%
- Cost-per-Task Over Cost-per-Token
Every source above answers which model or harness is cheaper. Simon Willison (2026-07-03,…
- Design by Selection
Not for shipping production software. "If you're shipping production software, stick with Claude…
- Disposable Micro-Apps
Claude Code — the product used to generate the throwaway UIs on demand
- Where Does Agent Harness Work Remain Durable as Models Improve?
Harness Shrinkage As Models Improve gives the negative space. Early Claude Code needed aggressive…
- Emergent
Indian AI coding / app-builder startup ("basically getting an engineering team in a box," per…
- Firm AI-Spend Intensity and Headcount Growth
US software-development postings +15% since Claude Code's launch (the series is indexed to 100 at…
- Follow-Up Fixes on Agent PRs
A merged pull request usually counts as finished work. Takerngsaksiri, Duong & Barnett (who…
- Founder as Agent Orchestrator
Claude Code / Cowork / Anthropic — the surfaces orchestration runs on
- The Future of Agent Interfaces
MCP's durable value is simple: it makes external systems agent-legible. A server exposes typed…
- Gemini Enterprise Agent Platform
The Google-side counterpart to Claude Code's and Codex's agent stacks — but where those entries…
- Guarantees That Degrade at Deployment: Action-Space Soundness, Admissibility Without Effect, and a Vendor-Coupled Security Framework
Concept pages: Reasoning Acting Interleaving, Continuous Self Modification Under Review, Zero Trust…
- Harness Shrinkage as Models Improve
The harness — prompts, skills, scaffolding, mechanical verification — exists to compensate for what…
- HTML as the New Markdown
Claude Code — the product these HTML-artifact workflows run in, demonstrated from inside the Claude…
- Jarred Sumner
Everything Sumner reports here is case-study with an explicit disclosure: an Anthropic employee,…
- Latent Capability Overhang
Boris Cherny (YC interview, July 2026, practitioner-opinion) names the same gap from the product…
- Living Design System
Claude Code — extracts the design DNA from repos and renders design_system.html; Claude Design…
- Managers as ICs
Fiona Fung's "spicy" org change on Claude Code: every manager starts as an IC first and stays…
- MCP Tool Poisoning
Claude Code — named as a prominent MCP host; the class of agent this threat targets, and one of the…
- Misalignment in Production Agent Traffic
Claude Code — the harness most of this traffic runs on; the --no-verify instruction, the hooks, the…
- Entities — People, Orgs, Tools & Projects
Claude Code — Anthropic's agentic coding product; created by Boris Cherny late 2024;…
- Nate Parrott
Claude Code — was the sole product designer on Claude Code for VS Code; also the…
- Observability-Pipeline Poisoning
Claude Code — the agent the 90% Cloudflare figure and the Datadog chain were run against
- Optimizer–Evaluator Decoupling
Claude Code v2.1.215 — the rule enforced by removing an affordance rather than by design. The…
- Orchestration vs Employee Framing: Reconciling the Founder's Playbook with HBR's Accountability Evidence
The playbook's lifecycle structure — Idea / MVP / Launch / Scale, each stage compressing what used…
- Parallel Agent Orchestration
Two numbers from it belong on this page. Fan-out width should vary with depth, and no fixed setting…
- Peter Steinberger
This is the seed of Loop Engineering — the shift from human-as-prompter to human-as-loop-designer.…
- Pilot-to-Production Gap
Claude Code — named as the worked example for the leading-vs-lagging indicator argument: PR cycle…
- Problem-Solution Fit Discipline
Idea-stage thesis: three defenses against premature building (time, resources, belief friction) all eroded; AI as devil…
- Recursive Self-Improvement
2025–2026 — Coding agents. Agents write and edit whole files on their own (Claude Code launches Feb…
- Same-Model Review Blindness
Two datasets of 500 pull requests each, one authored by Claude Code and one by Codex, identified by…
- Security Debt of Agent-Generated Code
Agent and language stratification (Figure 4, corpus average 38.9%): Copilot 45.5%, Claude Code…
- Standardize the Infrastructure, Not the Tools
The mechanism is an internal LLM proxy — a single gateway every AI request passes through before…
- The Stolen Model-Access Economy
Claude Code — spoofed by credential-harvesting installers on fake AI-reseller sites; the harness's…
- Verification as the New Bottleneck
Fiona Fung's central claim from running Claude Code + Cowork engineering: for years, engineering…
- When Does Verification Quality Determine Whether AI Automation Works?
That is why Verification As The New Bottleneck is the org-level consequence of the Verifiability…
- Vibe Coding vs. Agentic Engineering
Vibe coding raises the floor (anyone builds); agentic engineering preserves the quality bar while going faster; ">10x a…
Related articles
- Anthropic
AI safety company / vendor of Claude; mission-as-tiebreaker culture; ~30–40 PMs across teams; Mike Krieger leads Labs r…
- Harness Shrinkage as Models Improve
Prompt scaffolding shrinks each model release; Cat Wu's pruning discipline; Boris Cherny "100 lines of code a year from…
- Open Questions Backlog
Generated by `_system/lint.py --write-backlog`. Do not hand-edit. Domain and Watching sections carry one row per page —…
- Verification as the New Bottleneck
Fiona Fung: coding is no longer the bottleneck — verification, review, maintenance are; shift-left; TDD loses its tax;…
- Boris Cherny
Creator of Claude Code at Anthropic; phone-driven workflow with hundreds of agents; primary advocate of `/loop` primiti…
